Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Libopenmpt MEDIUM 6.5
CVE-2018-20861

libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.

Fix: 0.3.11+
Fix from $1,600 2019-07-30
Cpanel CRITICAL 9.8
CVE-2018-20863

cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).

Fix: 76.0.8+
Fix from $2,300 2019-07-30
Cpanel MEDIUM 6.5
CVE-2018-20864

cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).

Fix: 76.0.8+
Fix from $1,600 2019-07-30
Cpanel HIGH 7.8
CVE-2018-20869

cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).

Fix: 76.0.8+
Fix from $1,950 2019-07-30
Virtual Computing Lab CRITICAL 9.8
CVE-2018-11773

Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as a…

Fix: after 2.5
Fix from $2,300 2019-07-29
Edx Platform MEDIUM 5.3
CVE-2016-10765

edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.

Fix: 2016-06-10+
Fix from $1,600 2019-07-29
Samlr HIGH 7.5
CVE-2018-20857

Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with [email protected] followed by <!---->. and then the attacker…

Fix: 2.6.2+
Fix from $1,950 2019-07-26
Ipq4019 Firmware MEDIUM 5.5
CVE-2019-2330

improper input validation in allocation request for secure allocations can lead to page fault. in Snapdragon Auto, Snapdragon Compute, Snapdragon Con…

Patch available
Fix from $1,600 2019-07-25
Proxyprotocol HIGH 7.5
CVE-2019-14243

headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, allows re…

Fix: 0.0.2+
Fix from $1,950 2019-07-23
Firefox CRITICAL 10.0
CVE-2019-11708 KEVEPSS 56%

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent …

Fix: 60.7.2 / 67.0.4+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11714

Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerabili…

Fix: 68.0+
Fix from $2,300 2019-07-23
Firefox HIGH 8.3
CVE-2019-11716

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(…

Fix: 68.0+
Fix from $1,950 2019-07-23
Firefox HIGH 7.8
CVE-2019-11696

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can…

Fix: 67.0+
Fix from $1,950 2019-07-23
Firefox MEDIUM 6.5
CVE-2019-11697

If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt d…

Fix: 67.0+
Fix from $1,600 2019-07-23
Firefox MEDIUM 5.3
CVE-2019-11698

If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the …

Fix: 60.7.0 / 67.0+
Fix from $1,600 2019-07-23
Decorate Home Project HIGH 7.5
CVE-2019-13097

The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but ar…

No fix yet
Fix from $1,950 2019-07-22
Open Network Operating System CRITICAL 9.8
CVE-2019-1010234

The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands …

Fix: after 1.15.0
Fix from $2,300 2019-07-22
Phantompdf HIGH 7.5
CVE-2019-14211

An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the lack of proper validation of the existence of an ob…

Fix: 8.3.11+
Fix from $1,950 2019-07-21
Jetson Tx1 Firmware MEDIUM 6.7
CVE-2019-5680

In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is lo…

Mitigation only
Fix from $1,600 2019-07-19
Open Network Operating System CRITICAL 9.8
CVE-2019-1010245

The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can ex…

Fix: after 1.15
Fix from $2,300 2019-07-19
Campaign HIGH 7.5
CVE-2019-7843

Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Insufficient input validation vulnerability. Successful exploitation could l…

Fix: after 18.10.5.8984
Fix from $1,950 2019-07-18
Suricata HIGH 7.5
CVE-2019-1010251

Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An atta…

Patch available
Fix from $1,950 2019-07-18
Aironet 3700e Firmware HIGH 7.4
CVE-2019-1920

A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacen…

Fix: 8.2.170.0 / 8.3.150.0+
Fix from $1,950 2019-07-17
Spa501g Firmware MEDIUM 6.6
CVE-2019-1923

A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the devi…

Fix: after 7.6.2sr5
Fix from $1,600 2019-07-17
Whatsapp MEDIUM 5.3
CVE-2019-3571

An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be di…

Fix: 0.3.3793+
Fix from $1,600 2019-07-16
Fedora HIGH 7.5
CVE-2019-10190

A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass …

Fix: 4.1.0+
Fix from $1,950 2019-07-16
Fedora HIGH 7.5
CVE-2019-10191

A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains…

Fix: 4.1.0+
Fix from $1,950 2019-07-16
Perceptive Content Server HIGH 7.5
CVE-2018-19629

A Denial of Service vulnerability in the ImageNow Server service in Hyland Perceptive Content Server before 7.1.5 allows an attacker to crash the ser…

Fix: 7.1.5+
Fix from $1,950 2019-07-16
Mdaemon Email Server HIGH 7.5
CVE-2019-13612

MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even wit…

Mitigation only
Fix from $1,950 2019-07-16
.net Framework HIGH 8.8
CVE-2019-1113EPSS 10%

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successful…

Patch available
Fix from $1,950 2019-07-15